Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Analizada | Crítica (9.8) | 2.6% | ⚠ Explotación activa | Vmware Vcenter Server | 30/7/2026 | 19/8/2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.61% | — | Vmware Vcenter Server | 30/7/2026 | 25/8/2026 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. | |
| Aplazada | Alta (8.5) | 0.64% | — | Vmware VcenterAI | 29/9/2025 | 17/6/2026 | VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks. | |
| Aplazada | Alta (7.6) | 0.28% | — | Vmware ToolsAIVmware VcenterAIVmware ESXAI | 29/9/2025 | 17/6/2026 | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation… | |
| Aplazada | Media (4.4) | 0.29% | — | Vmware VcenterAI | 29/7/2025 | 17/6/2026 | VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition. | |
| Aplazada | Alta (8.7) | 0.30% | — | HPE Oneview FOR Vmware VcenterAI | 26/6/2025 | 17/6/2026 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions). | |
| Aplazada | Media (4.3) | 0.89% | — | Vmware EsxiAIVmware Vcenter ServerAI | 20/5/2025 | 17/6/2026 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. | |
| Aplazada | Media (6.8) | 0.24% | — | Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI | 20/5/2025 | 17/6/2026 | VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools… | |
| Aplazada | Alta (8.8) | 0.26% | — | Vmware Vcenter ServerAI | 20/5/2025 | 17/6/2026 | The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server. | |
| Analizada | Crítica (9.8) | 17% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 17/9/2024 | 17/6/2026 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. | |
| Analizada | Crítica (9.8) | 55% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 17/9/2024 | 17/6/2026 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Media (5.3) | 0.71% | — | Vmware Cloud FoundationVmware Vcenter Server | 25/6/2024 | 17/6/2026 | The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. | |
| Aplazada | Media (4.4) | 0.14% | — | Hitachi Storage Provider FOR Vmware VcenterAI | 25/6/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4. | |
| Analizada | Alta (7.8) | 5.0% | — | Vmware Vcenter ServerVmware Cloud Foundation | 18/6/2024 | 17/6/2026 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. | |
| Modificada | Crítica (9.8) | 12% | — | Vmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Crítica (9.8) | 22% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Media (4.9) | 0.99% | — | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | |
| Analizada | Alta (7.2) | 2.5% | — | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system. | |
| Modificada | Media (4.3) | 0.67% | — | Vmware Vcenter Server | 25/10/2023 | 17/6/2026 | vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Vmware Vcenter Server | 25/10/2023 | 17/6/2026 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | |
| Modificada | Alta (7.5) | 0.90% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and… | |
| Modificada | Crítica (9.8) | 1.4% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication. | |
| Modificada | Crítica (9.8) | 34% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.2% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server. |